Confessions of the QSA: An Introduction to the Payment Card Industry Data Security Standard

 

As most in the industry know, a QSA must get certified by the PCI Security Standards Security Council to audit merchants for Payment Card Industry Data Security Standard (PCI DSS) compliance. Created in 2004 by major credit card brands, such as Visa and American Express, the council acts as a form of self-regulation.

So, how did Weaver become an expert on PCI, and what types of solutions does it offer its clients?

On this episode of Weaver: Beyond The Numbers, host Tyler Kern talked with Trip Hillman, Director of Cyber Security Services at Weaver, and Kyle Morris, Manager of IT at Advisory Services at Weaver. The trio dug into insights from Weaver’s Quality Security Assessor and explored how Weaver dove headfirst into PCI.

The PCI DSS applies to organizations that store, process, transmit or could affect the security of cardholder data. Companies that fall under this standard could do a variety of things, such as an annual self-assessment questionnaire, or bring in a third-party, independent QSA to do a full-blown report on compliance audit.

Morris is a QSA and started at Weaver about eight years ago. A few years into his career, they had a client, a service provider, start getting asked by their customers if they knew anything about PCI and the report on compliance. At the time, they hadn’t done anything with it, but decided to figure it out. That morphed into Weaver diving headfirst into PCI.

“We help people with self-assessment questionnaires or SAQs and everything from full-on ROCs for Fortune 50 Cloud Providers to small merchants to SaaS solutions,” Morris said.

Follow us on social media for the latest updates in B2B!

Image

Latest

team
Why Treating Everyone the Same Is Hurting Your Team
January 28, 2026

For years, management best practices emphasized uniformity: standard processes, standardized expectations, and treating everyone the same in the name of fairness. But today’s workforce looks very different than it did in the late 1990s and early 2000s. With multi-generational teams, shifting attitudes toward work-life balance, and an increased focus on emotional intelligence, leaders are…

Read More
giving back
Corporate Heartbeat: The Win-Win of Giving Back
January 28, 2026

Corporate giving is increasingly viewed as part of local economic infrastructure—not discretionary generosity. In the U.S., 13.7% of households experienced food insecurity in 2024, impacting millions of working families and signaling stress within regional labor markets. As cost-of-living pressures persist and metro regions like North Texas continue to grow rapidly, business leaders are reassessing…

Read More
setting scope
Crafted Journey How To: Setting Scope, Saving Sanity, and Protecting Long-Term Client Value
January 27, 2026

The independent workforce continues to grow, with professionals increasingly choosing solo and fractional paths over traditional employment. The U.S. Bureau of Labor Statistics reports that independent contractors now represent 11.9 million workers, or about 7.4% of total U.S. employment. Without the structural guardrails of traditional roles, independent professionals must define scope, success, and boundaries…

Read More
Culture of Safety
Beyond Drills: Building a Culture of Safety in Schools
January 27, 2026

School Safety Today podcast, presented by Raptor Technologies. In this episode of Principals of Change, host Dr. Amy Grosso sits down with Jeff Bryant, Principal of Jefferson Middle School, and David Sally, Associate Principal of West Aurora High School, to explore how effective school safety goes far beyond drills and locked doors. Drawing on…

Read More